CVE-2026-29067: ZITADEL: Account Takeover Due to Improper Instance Validation in V2 Login
ZITADEL is an open source identity management platform. From version 4.0.0-rc.1 to 4.7.0, a potential vulnerability exists in ZITADEL's password reset mechanism in login V2. ZITADEL utilizes the Forwarded or X-Forwarded-Host header from incoming requests to construct the URL for the password reset confirmation link. This link, containing a secret code, is then emailed to the user. This issue has been patched in version 4.7.1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-29067?
CVE-2026-29067 is classified as a high severity vulnerability due to its potential for account takeover.
How do I fix CVE-2026-29067?
To mitigate CVE-2026-29067, upgrade ZITADEL to version 4.7.1 or later where the vulnerability has been addressed.
What versions of ZITADEL are affected by CVE-2026-29067?
CVE-2026-29067 affects ZITADEL versions from 4.0.0-rc.1 to 4.7.0.
What is the impact of CVE-2026-29067?
CVE-2026-29067 may allow an attacker to take over user accounts via improper instance validation.
Is CVE-2026-29067 a zero-day vulnerability?
CVE-2026-29067 is not classified as a zero-day vulnerability, but it still poses significant risks if not patched.